diff --git a/apps/gooyal_oauth2/migrations/0006_remove_scope_resource_remove_application_resource_and_more.py b/apps/gooyal_oauth2/migrations/0006_remove_scope_resource_remove_application_resource_and_more.py index 691e9b2..ee76906 100644 --- a/apps/gooyal_oauth2/migrations/0006_remove_scope_resource_remove_application_resource_and_more.py +++ b/apps/gooyal_oauth2/migrations/0006_remove_scope_resource_remove_application_resource_and_more.py @@ -21,7 +21,7 @@ class Migration(migrations.Migration): migrations.AddField( model_name='application', name='max_allowed_session', - field=models.PositiveIntegerField(default=1), + field=models.PositiveIntegerField(default=0), ), migrations.AlterField( model_name='application', diff --git a/apps/gooyal_oauth2/models.py b/apps/gooyal_oauth2/models.py index 61c1c5a..89bcab1 100644 --- a/apps/gooyal_oauth2/models.py +++ b/apps/gooyal_oauth2/models.py @@ -38,7 +38,7 @@ class Application(AbstractApplication, BaseModel): allowed_scope = models.TextField(blank=True) avatar = models.ImageField(upload_to='avatars', null=True, blank=True) - max_allowed_session = models.PositiveIntegerField(default=1) + max_allowed_session = models.PositiveIntegerField(default=0) @property diff --git a/apps/gooyal_oauth2/throttling.py b/apps/gooyal_oauth2/throttling.py index 6373213..392cabf 100644 --- a/apps/gooyal_oauth2/throttling.py +++ b/apps/gooyal_oauth2/throttling.py @@ -26,6 +26,9 @@ class TokenLimitThrottle: if max_allowed_session >= session_count: return True else: + from utils.exceptions import Conflict + raise Conflict(code='max_allowed_session_reached') + active_tokens = AccessToken.objects.filter( application=application, user=request.user ).order_by("created")[:max_allowed_session].values_list("token", flat=True) @@ -37,3 +40,8 @@ class TokenLimitThrottle: else: return True + + return True + + def wait(self): + pass diff --git a/apps/users/views.py b/apps/users/views.py index c2b6e62..9607ec6 100644 --- a/apps/users/views.py +++ b/apps/users/views.py @@ -187,6 +187,8 @@ class UserSessionListView(generics.ListAPIView): serializer_class = SessionSerializer filter_backends = (DjangoFilterBackend,) + max_allowed_session = 0 + required_alternate_scopes = { "GET": [["accounts.account:retrieve"]], } diff --git a/utils/exceptions.py b/utils/exceptions.py index 8c9c36d..ca3ac1e 100644 --- a/utils/exceptions.py +++ b/utils/exceptions.py @@ -56,6 +56,7 @@ def exception_handler(exc, context): # در فایل middleware.py from django.http import JsonResponse + class ErrorMiddleware: def __init__(self, get_response): self.get_response = get_response @@ -76,6 +77,7 @@ class ErrorMiddleware: status=500 ) + from rest_framework.exceptions import APIException from rest_framework import status from django.utils.translation import gettext_lazy as _ @@ -86,6 +88,7 @@ class UnprocessableEntity(APIException): default_detail = 'The request was well-formed but cannot be processed due to semantic errors.' default_code = 'unprocessable_entity' + class ServiceUnavailable(APIException): status_code = status.HTTP_503_SERVICE_UNAVAILABLE default_ = _('SERVICE_UNAVAILABLE')